Thread (175 messages) flat view 175 messages, 9 authors, 9d ago

Re: [PATCH v13 7/8] history: create squashed commits without editing

From: Junio C Hamano <hidden>
Date: 2026-08-17 15:24:39

Phillip Wood [off-list ref] writes:
It's piped into "tr" to check that

	target = lookup_commit_reference_by_name(s);
	if (target && istarts_with(oid_to_hex(&target->object.oid), s))

uses istarts_with() so that we accept uppercase object ids.
You should check in with brian about istarts_with() that is used
here, as I suspect he missed it in his effort to declare uppercase
hexadecimal literals invalid.  In the meantime, '| tr' must be
removed if this topic wants to play nicely with the
'bc/restrict-hex-to-lowercase' topic.  In my fixup patch, I changed
it to use 'rev-parse --short' to test at least the "starts with"
aspect of this code.
I've just had a quick look at that other thread, it would be more 
convincing to me if there was some explanation of the security issues 
that accepting uppercase object ids causes. While I appreciate brian may 
not be able to talk about specific vulnerabilities in particular 
products, it would help to outline the security issues in general terms.
True.


Thanks.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help